CVE-2014-8008

Cisco Unified Communications Manager - Information Disclosure

Title source: rule
STIX 2.1

Description

Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414.

Exploits (1)

exploitdb WRITEUP
by Bernhard Mueller · textwebappsmultiple
https://www.exploit-db.com/exploits/37816

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72263
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031604
Various Sources vendor-advisory x_refsource_cisco
https://tools.cisco.com/security/center/viewAlert.x?alertId=37111

Scores

EPSS 0.0902
EPSS Percentile 92.7%

Details

CWE
CWE-200
Status published
Products (1)
cisco/unified_communications_manager
Published Jan 22, 2015
Tracked Since Feb 18, 2026